High School IntermediateModule I14Lesson 8 of 8

I14.8 Security Policies and Risk Lab

Complete an integrated fictional Northbridge case combining governance, assets, data, business impact, risk assessment, treatment, controls, policies, exceptions, suppliers, metrics, leadership reporting, validation, and review.

Lesson Progress

Security Policies and Risk Lab

High School IntermediateI14: Security Policies and Risk • Lesson 8 of 8

100% complete

Readiness Check

Before You Start

0/5 ready

Integrated Case

Northbridge Needs a Decision-Ready Governance and Risk Package

The fictional Northbridge leadership team has asked for one integrated review. The organization has an overdue security policy, active supplier access under an expired exception, unclear business recovery ownership, an untested backup assumption, cloud concentration, partial storage evidence, misleading metric scope, and an unowned supplier-offboarding lesson. Your job is to convert these records into accountable, prioritized, evidence-based decisions without exaggerating incidents or impact.

Weak integrated response

Label everything critical, assume compromise, recommend every control, ignore authority and dependencies, and provide a dashboard with no decisions or evidence limits.

Professional integrated response

Define scope, map ownership, validate evidence, structure risk, compare treatment, prioritize active exposure, preserve limits, assign decisions, test controls, and report clearly.

Objective 1

Integrate fictional governance, assets, data, business impact, risk assessment, treatment, standards, exceptions, suppliers, metrics, reporting, and review into one defensible case.

Objective 2

Separate fictional direct observations, supported conclusions, assumptions, alternatives, uncertainty, missing evidence, potential impact, confirmed impact, and decision authority.

Objective 3

Build a fictional governance and risk package with owners, evidence, controls, treatment, deadlines, validation, residual-risk decisions, monitoring, and closure criteria.

Objective 4

Prioritize fictional actions using business criticality, active exposure, control health, supplier dependency, recovery needs, confidence, and implementation readiness.

Objective 5

Create a portfolio-safe fictional capstone artifact that demonstrates professional reasoning without using real organizational records, credentials, incidents, or private data.

Core Model

Use the Scope–Evidence–Risk–Decision–Validation Cycle

Scope

Define the fictional business question, services, data, suppliers, users, owners, authority, time window, and privacy limits.

Evidence

Validate fictional relevance, health, completeness, timeliness, independence, traceability, assumptions, and limitations.

Risk

Connect fictional assets, threats, vulnerabilities, exposure, controls, likelihood, impact, confidence, and dependencies.

Decision

Select fictional treatment, controls, owners, approvals, deadlines, exceptions, communication, and residual-risk authority.

Validation

Test fictional security outcome, business function, evidence, monitoring, recovery, closure, and reassessment triggers.

Key Vocabulary

Integrated Governance and Risk Terms

Governance package

A fictional collection of charters, responsibility maps, policies, standards, controls, evidence, decisions, exceptions, metrics, and review records.

Risk register

A fictional record of scenarios, assets, threats, vulnerabilities, controls, likelihood, impact, confidence, owners, treatments, and review dates.

Business-impact analysis

A fictional analysis of critical services, dependencies, disruption effects, recovery objectives, minimum service, and recovery priorities.

Control objective

A fictional statement describing the business or security outcome that a safeguard must achieve.

Residual risk

The fictional risk remaining after current or planned controls, limitations, dependencies, exceptions, and uncertainty are considered.

Compensating control

A fictional alternate safeguard that addresses the same control objective when the preferred control is temporarily impractical.

Exception

A fictional approved and time-bound departure from a requirement with narrow scope, owners, controls, residual risk, expiration, monitoring, and sunset planning.

Third-party risk

A fictional risk arising from suppliers, service providers, software components, data processors, subcontractors, or external dependencies.

Metric definition

A fictional description of a metric’s purpose, scope, numerator, denominator, exclusions, source, frequency, target, threshold, owner, and limits.

Evidence confidence

A fictional judgment about how strongly the supplied records support a conclusion.

Decision authority

The fictional approved power to accept risk, approve policy, authorize an exception, fund treatment, escalate delay, or close a finding.

Validation

Fictional evidence that a control, recovery path, process, exception removal, supplier exit, or corrective action works as intended.

Closure criteria

Fictional conditions that must be satisfied before a finding, risk, exception, treatment, or action is considered complete.

Reassessment trigger

A fictional date or event that requires renewed review, such as a major change, failed test, incident, supplier change, deadline, or evidence gap.

Leadership summary

A fictional concise report that translates technical and risk evidence into business meaning, uncertainty, options, ownership, and decisions.

Portfolio-safety statement

A statement confirming that all organizations, systems, identities, suppliers, records, incidents, and evidence in the artifact are fictional.

Case Overview

Eight Fictional Conditions to Integrate

Governance

Direct observation

The fictional Information Security Policy is overdue for annual review.

Supported meaning

Current owners, scope, requirements, and business priorities need formal reassessment.

Evidence limit

An overdue review does not prove the policy or controls are ineffective.

Supplier access

Direct observation

One fictional support-vendor account remains active after the project and exception ended.

Supported meaning

The account requires immediate removal or narrow authorized renewal.

Evidence limit

No unauthorized use, malicious intent, or disclosure is confirmed.

Recovery ownership

Direct observation

The fictional Reporting Service has technical operators but no confirmed business recovery risk owner.

Supported meaning

Business authority for recovery priority and residual risk is unclear.

Evidence limit

Technical recovery failure is not proven.

Data recovery

Direct observation

One fictional historical support collection is outside backup scope because the owner believes it can be reconstructed.

Supported meaning

Reconstruction must be tested or recovery protection added.

Evidence limit

No current data loss is confirmed.

Metrics

Direct observation

The fictional dashboard reports ninety-eight percent policy compliance without a documented denominator or excluded-system list.

Supported meaning

Organization-wide interpretation is unsupported.

Evidence limit

The measured systems may still perform strongly.

Supplier concentration

Direct observation

Several fictional critical services depend on one cloud platform.

Supported meaning

Regional, recovery, evidence-access, and exit planning require review.

Evidence limit

No provider-controlled outage or incident is shown.

Incident improvement

Direct observation

A fictional supplier-offboarding lesson remains open without a policy or procedure owner.

Supported meaning

The weakness may recur unless converted into owned governance and control changes.

Evidence limit

Some operational improvement may exist outside the supplied tracker.

Security evidence

Direct observation

One fictional storage source provides partial rather than complete object-level activity evidence.

Supported meaning

Monitoring confidence is reduced and compensating evidence must be reviewed.

Evidence limit

Partial evidence does not prove compromise.

Evidence Register

Eight Fictional Evidence Sources

EV-01

Policy register

Supports

Policy owner, approval, version, effective date, review cycle, current status, and overdue review.

Source health

Current metadata; policy content requires formal review.

Limitation

Does not prove daily control operation.

EV-02

Supplier access register

Supports

Account status, sponsor, project end, role scope, exception expiration, and service boundary.

Source health

Account and exception records are current.

Limitation

Post-expiration activity coverage is incomplete.

EV-03

Asset and dependency register

Supports

Critical services, data, suppliers, owners, identities, networks, recovery dependencies, and concentration.

Source health

Most records are current; one recovery owner is missing.

Limitation

Informal dependencies may exist outside the register.

EV-04

Risk register

Supports

Risk scenarios, inherent and residual scores, confidence, treatment status, owners, and review dates.

Source health

Current enough for the lab; one acceptance review is overdue.

Limitation

Several scores depend on incomplete activity or ownership evidence.

EV-05

Recovery exercise records

Supports

RTO, RPO, technical restore, minimum service, user validation, dependencies, and exercise outcomes.

Source health

Technical records are complete; business validation is partial.

Limitation

One exercise does not guarantee future recovery.

EV-06

Exception register

Supports

Requirements, scope, business reason, controls, approvals, expiration, monitoring, residual risk, and sunset actions.

Source health

Current; one exception is expired and one request is incomplete.

Limitation

Exception documentation does not prove compensating-control effectiveness.

EV-07

Supplier evidence register

Supports

Criticality, contracts, access, data, control evidence, incidents, recovery, fourth parties, and exit readiness.

Source health

Mostly current; one report’s service and region scope is unclear.

Limitation

One assurance report cannot prove every supplier control.

EV-08

Metrics dashboard and definitions

Supports

Compliance, access review, supplier evidence, recovery, exception currency, source health, treatment progress, and improvement closure.

Source health

Values are current; several definitions need correction.

Limitation

Percentages may hide exclusions, quality, and incomparable scopes.

Lab Workflow

Complete the Integrated Case in Eight Phases

1

Establish the charter

Define the fictional business question, scope, assets, services, data, suppliers, owners, authority, evidence, time window, privacy boundary, and expected decisions.

Deliverable: Integrated lab charter.

2

Map governance and ownership

Assign fictional executive, risk, policy, control, asset, data, supplier, recovery, metrics, incident, review, and escalation responsibilities.

Deliverable: Responsibility and authority matrix.

3

Map assets and impact

Connect fictional services, data, users, identities, suppliers, processes, facilities, dependencies, criticality, RTO, RPO, minimum service, and recovery priorities.

Deliverable: Asset, dependency, and BIA package.

4

Build risk scenarios

Document fictional threats, vulnerabilities, exposure, controls, likelihood, impact, assumptions, confidence, alternatives, limits, and owners.

Deliverable: Integrated risk register.

5

Select treatments and controls

Compare fictional avoid, reduce, transfer, accept, and monitor options with control objectives, business fit, dependencies, validation, rollback, and residual risk.

Deliverable: Treatment and control plan.

6

Review policies and exceptions

Map fictional policies, standards, baselines, procedures, guidelines, controls, evidence, exceptions, approvals, expiration, monitoring, and sunset plans.

Deliverable: Document hierarchy and exception register.

7

Review suppliers and metrics

Evaluate fictional supplier scope, access, data, contract controls, concentration, evidence, incidents, recovery, exit, metric definitions, source health, trends, and leadership meaning.

Deliverable: Supplier and metrics review.

8

Prioritize, communicate, and close

Rank fictional actions, assign owners and deadlines, document leadership decisions, validate controls, define reassessment triggers, and produce technical and executive summaries.

Deliverable: Final governance and risk package.

Required Portfolio Artifacts

Ten Deliverables for the Final I14 Package

1

Integrated lab charter with scope, authority, evidence boundary, privacy boundary, owners, deliverables, and decision deadlines.

2

Governance responsibility matrix covering executive, risk, policy, control, asset, data, supplier, recovery, metrics, incident, review, and escalation roles.

3

Asset, service, data, supplier, user, dependency, classification, criticality, RTO, RPO, minimum service, and recovery-priority register.

4

Evidence-quality register with relevance, source health, independence, timeliness, completeness, consistency, traceability, confidence, and limitations.

5

Risk register with structured scenarios, controls, inherent and residual likelihood and impact, assumptions, alternatives, owners, treatments, and review triggers.

6

Risk-treatment and control-selection plan with control objectives, business fit, implementation sequence, validation, rollback, monitoring, and residual-risk approval.

7

Policy, standard, baseline, procedure, guideline, control, evidence, exception, waiver, approval, review, and sunset hierarchy.

8

Third-party and supply-chain register with services, fourth parties, software components, data, access, responsibilities, concentration, incidents, recovery, monitoring, and exit.

9

Metrics catalog with purpose, scope, numerator, denominator, exclusions, source health, target, threshold, trend, confidence, owner, business meaning, and actions.

10

Technical report, leadership summary, action register, validation plan, reassessment plan, reflection, and portfolio-safety statement.

Integrated Case Records

Northbridge Fictional Governance and Risk Register

NBR-LAB-01

Expired supplier access

Third-Party Risk Owner

Facts

Project ended; exception expired; one limited account remains active; post-expiration activity evidence is incomplete.

Risk

Medium likelihood and High potential impact with Medium-High confidence.

Decision

Remove or narrowly renew through authorized governance.

Validation

Account is removed or matches renewed scope; approved support remains functional; monitoring is healthy.

Evidence limit

No unauthorized use or disclosure is confirmed.

NBR-LAB-02

Recovery ownership gap

Business Service Executive

Facts

Reporting Service has a procedure, two technical operators, and a four-hour RTO, but no business recovery owner.

Risk

Medium likelihood and High potential impact with Medium confidence.

Decision

Assign business authority and repeat user validation.

Validation

Owner approves priority, minimum service, exercise result, and residual risk.

Evidence limit

Technical recovery failure is not proven.

NBR-LAB-03

Historical backup exclusion

Support Data Owner

Facts

One confidential historical collection is outside backup scope; the owner claims it can be reconstructed.

Risk

Residual risk cannot be finalized until reconstruction evidence exists.

Decision

Run a timed reconstruction test or add backup coverage.

Validation

Reconstruction or restore meets approved RTO, completeness, integrity, and access requirements.

Evidence limit

No current data loss is confirmed.

NBR-LAB-04

Policy metric ambiguity

Security Metrics Owner

Facts

Dashboard shows ninety-eight percent compliance; excluded legacy systems and denominator are not documented.

Risk

Medium decision-quality risk with High confidence.

Decision

Correct the definition before organization-wide use.

Validation

A reviewer can reconstruct the calculation, scope, exclusions, source health, and trend.

Evidence limit

Measured-system performance may be strong.

NBR-LAB-05

Cloud concentration

Cloud Service Owner

Facts

Learning, identity, storage, monitoring, and recovery capabilities rely on one fictional cloud platform.

Risk

High structural concentration with Medium-Low current service risk.

Decision

Maintain tested regional recovery, internal evidence access, data portability, and exit planning.

Validation

Recovery and exit exercises demonstrate minimum service, data access, evidence preservation, and owner decisions.

Evidence limit

No provider-controlled incident is shown.

NBR-LAB-06

Partial object logging

Security Operations and Support Data Owner

Facts

One storage collection has function-level and change evidence but incomplete object-level activity logs.

Risk

Medium monitoring and investigation risk.

Decision

Maintain compensating controls and replace the connector within the approved exception window.

Validation

Expected object events arrive, parse, retain, alert, and support investigation.

Evidence limit

Partial evidence does not prove compromise.

NBR-LAB-07

Unowned incident improvement

Governance Improvement Lead

Facts

Supplier-offboarding improvements were recommended, but policy and procedure ownership is missing.

Risk

Medium-High recurrence risk.

Decision

Assign owners, update the procedure, run an offboarding exercise, and validate closure.

Validation

Access, data, integrations, notifications, monitoring, knowledge transfer, and signoff complete on time.

Evidence limit

Some undocumented operational improvements may exist.

NBR-LAB-08

Overdue policy review

Security Policy Owner

Facts

The Information Security Policy is six fictional months beyond its annual review date.

Risk

Medium governance risk with High confidence.

Decision

Complete stakeholder review, approval, publication, implementation mapping, and communication.

Validation

Current scope, owners, standards, controls, exceptions, training, and review dates are approved.

Evidence limit

The overdue review does not prove existing controls are ineffective.

Priority Action Plan

Six Ordered Fictional Actions

1

Resolve active stale supplier access

Third-Party Risk Owner

Why now

The fictional account remains active after project and exception closure, creating current capability and governance risk.

Deadline

Within one fictional business day

Closure proof

Removal or narrow renewal, activity review, service validation, monitoring, and owner signoff.

2

Assign business recovery ownership

Business Service Executive

Why now

A fictional critical service lacks authority for recovery priority, minimum service, validation, and residual risk.

Deadline

Within three fictional business days

Closure proof

Named owner, approved objectives, exercise participation, decision record, and review date.

3

Validate backup exclusion

Support Data Owner

Why now

A fictional confidential historical collection depends on an untested reconstruction assumption.

Deadline

Within ten fictional business days

Closure proof

Timed reconstruction or restore test with completeness, integrity, access, and owner approval.

4

Correct leadership metrics

Security Metrics Owner

Why now

The fictional compliance metric lacks a denominator and exclusions, creating decision-quality risk.

Deadline

Before the next fictional leadership meeting

Closure proof

Definition, calculation, scope, exclusions, source health, confidence, trend, and action rules.

5

Assign and test supplier-offboarding ownership

Governance Improvement Lead

Why now

A fictional lesson learned remains unowned and may not become a lasting governance change.

Deadline

Within fifteen fictional business days

Closure proof

Updated policy and procedure, assigned roles, exercise, evidence, exceptions, monitoring, and closure.

6

Complete policy review

Security Policy Owner

Why now

The fictional policy is overdue and service, supplier, metric, recovery, and exception conditions have changed.

Deadline

Within thirty fictional days

Closure proof

Reviewed and approved version, stakeholder comments, control mapping, communication, and next review date.

Fake Dashboard

Fake Northbridge Integrated Risk Dashboard

Training dashboard for fictional I14 lab evidence only.

Integrated records

8

Governance, supplier, recovery, backup, metrics, cloud concentration, monitoring, and improvement issues are mapped.

Immediate owner decisions

4

Stale access, recovery ownership, backup evidence, and metric scope require prompt decisions.

Confirmed incidents

0

The supplied fictional evidence supports control and governance gaps but no confirmed incident, misuse, outage, or disclosure.

Fake SOC Alert

Integrated Review Finds Active Stale Access and Missing Decision Authority

Source: Fake I14 Integrated Lab Console • Time: 4:00 PM

High Severity
A fictional supplier account remains active after project and exception closure, while a critical recovery service lacks a confirmed business risk owner.
Defensive recommendation: Prioritize access removal or narrow renewal and assign recovery decision authority. Preserve evidence, confirm business needs, validate controls and service behavior, document residual risk, monitor, and avoid claiming misuse or recovery failure without support.

Fake Log Panel

Fake Northbridge Integrated Lab Timeline

training-log-viewer.log
09:00 CHARTER scope='I14 integrated governance and risk lab'
09:10 GOVERNANCE policy-review='overdue'
09:20 SUPPLIER account='active' exception='expired'
09:30 RECOVERY business-owner='missing'
09:40 BACKUP historical-collection='excluded'
09:50 METRIC compliance='98%' denominator='undefined'
10:00 CLOUD concentration='multiple critical services'
10:10 LOGGING object-evidence='partial'
10:20 IMPROVEMENT supplier-offboarding owner='missing'
10:30 FINDING confirmed-incident='not supported'
10:40 PRIORITY stale-access='1'
10:50 PRIORITY recovery-ownership='2'
11:00 PRIORITY backup-validation='3'
11:10 PRIORITY metrics-correction='4'
11:20 VALIDATION business-and-security='required'
11:30 CLOSE owner-signoff-and-reassessment='required'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Which Integrated Conclusion Is Most Defensible?

The fictional supplier project and exception ended.
One limited supplier account remains active.
A critical reporting service lacks a business recovery owner.
One historical collection is outside backup scope.
The leadership metric lacks a denominator and exclusions.
No supplied evidence confirms unauthorized use, provider incident, data loss, outage, or disclosure.

Which conclusion is strongest?

Common Mistakes

Mistakes That Weaken the Integrated I14 Lab

Starting the fictional lab with a preferred conclusion instead of a clear charter and evidence boundary.
Treating one dashboard, alert, exception, or account record as complete proof of an incident or business impact.
Confusing policy ownership, control ownership, risk ownership, asset ownership, data ownership, supplier ownership, and recovery ownership.
Scoring fictional risk without a structured scenario, evidence, time window, assumptions, controls, confidence, and limitations.
Treating potential impact as confirmed impact.
Choosing controls without testing business fit, dependencies, expected allowed behavior, denied behavior, monitoring, rollback, and recovery.
Using an exception without an exact requirement, control objective, narrow scope, owner, expiration, monitoring, residual risk, and sunset plan.
Treating supplier contracts or assurance reports as proof of current technical operation.
Publishing percentages without denominator, exclusions, source health, targets, thresholds, confidence, and decision rules.
Prioritizing document cleanup above active stale access, missing decision authority, or unvalidated recovery.
Closing actions because a ticket or document changed without validating the actual control and business outcome.
Hiding uncertainty, alternate explanations, missing sources, partial coverage, stale evidence, or ownership gaps.
Failing to define event-based reassessment triggers after major changes, incidents, failed tests, supplier changes, or expired approvals.
Using or exposing any real company policy, supplier contract, architecture, access record, employee identity, school data, credential, incident evidence, dashboard, risk register, or confidential business information.

Final Lab Assignment

Build the Complete Northbridge Security Policies and Risk Package

Your fictional assignment

Evidence, Governance, Risk, Controls, Suppliers, Metrics, and Decisions

Use only the fictional records on this page and the prior I14 lessons to produce a professional, decision-ready, portfolio-safe package.

Final quality standard

  • Every finding links to exact fictional evidence.
  • Every risk has an owner, treatment, deadline, and review trigger.
  • Every control has an objective, evidence, validation, monitoring, and closure test.
  • Every exception has scope, authority, expiration, residual risk, and sunset planning.
  • Every metric has a definition, source, denominator, exclusions, confidence, and decision use.
  • Every leadership statement separates facts, conclusions, uncertainty, potential impact, and confirmed impact.
All organizations, systems, identities, suppliers, services, records, incidents, metrics, and decisions in this lab are fictional. Do not use real private organizational information.

Scenario Decision Lab

Leadership Wants the Supplier Account Removed Immediately

The fictional supplier account is stale, but the service owner says one approved support task may still depend on it.

Scenario Decision Lab

The Dashboard Is Green, but Four Decisions Are Overdue

The fictional leadership dashboard shows mostly favorable percentages while stale access, missing recovery ownership, backup uncertainty, and an unowned improvement remain open.

Defender Habits

Security Policies and Risk Lab Checklist

Check Your Understanding

I14.8 Mini Quiz: Security Policies and Risk Lab

Choose your answers first. Explanations appear only after submission.

1. What is the strongest first step in the fictional I14 integrated lab?

2. Which issue should receive the highest immediate priority?

3. What does the fictional missing recovery owner prove?

4. How should the fictional historical backup exclusion be resolved?

5. What does the fictional ninety-eight percent policy-compliance metric support?

6. What is required before closing a fictional treatment action?

7. What makes the final fictional I14 lab package defensible?

Portfolio Prompt

Portfolio Prompt

Create a fictional Integrated Security Policies and Risk Package for Northbridge. Include the charter, governance and authority matrix, asset and BIA register, evidence-quality register, risk register, treatment and control plan, policy hierarchy, exception register, supplier and supply-chain review, metrics catalog, priority action plan, validation and closure criteria, reassessment triggers, technical report, leadership summary, reflection, and a portfolio-safety statement.

Use only fictional organizations, systems, services, identities, suppliers, data, evidence, incidents, dates, metrics, risks, and decisions.
Do not treat stale access, missing ownership, backup exclusions, provider concentration, partial logs, overdue reviews, or green dashboards as proof of compromise or harmlessness.
Make every conclusion traceable to evidence, confidence, limitations, owner authority, and the next decision.
Prioritize active stale access and missing business decision authority before lower-risk document polish.

Key Takeaways

What You Should Remember

1.Integrated governance and risk work connects business context, ownership, evidence, assets, risk, treatment, policy, suppliers, metrics, and review.
2.Active stale access can require immediate correction even when misuse is not proven.
3.Missing decision authority is a governance risk even when technical controls appear strong.
4.Recovery assumptions, metric definitions, compensating controls, and supplier evidence should be validated rather than trusted automatically.
5.Positive metrics and serious unresolved risks can exist at the same time.
6.Closure requires validated security and business outcomes, residual-risk approval, monitoring, owner signoff, and reassessment.
7.Portfolio artifacts should use fully fictional evidence and never expose real organizational records.

Navigation

Complete Module I14